Impact
VSee Clinic version 7.1.26 and its API 1.3.0 expose a vulnerable endpoint that allows an authenticated attacker to manipulate the 'remark' request parameter. This flaw enables enumeration, retrieval, and deletion of files belonging to other users, compromising confidentiality, integrity, and availability for those files. The weakness is an insecure direct object reference (CWE‑639) that bypasses normal ownership checks.
Affected Systems
The vulnerability affects deployments running VSee Clinic 7.1.26 and API 1.3.0; any installation using these versions is at risk of unauthorized file access and deletion.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs authenticated access to the application to manipulate the 'remark' parameter and target files owned by other users, making the exploit relatively easy if credentials are compromised.
OpenCVE Enrichment